At a glance
A photograph or video showing an identifiable individual is personal data under the DPDP Act, which puts event managers and photographers in an unusual spot — they’re Data Fiduciaries the moment they capture recognisable images of guests, and the consent question splits into two layers most of the industry treats as one: consent to be photographed, and consent to how the images are used (social media, a portfolio, a client’s marketing). A wedding guest agreeing to be photographed hasn’t automatically agreed to appear in the photographer’s public portfolio.
Educational resource only. This explains how the personal-data and consent rules under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) apply to event photography and videography; it is not formal legal advice.
The situation
Event photography runs on an assumption the industry rarely examines: that being invited to an event, or being visibly present at one, is itself a kind of blanket consent to being photographed and having those photos used however the photographer or event business sees fit. The DPDP Act doesn’t work from that assumption, and the gap between industry habit and the Act’s actual consent framework is where most of the sector’s exposure sits.
Is a photograph actually “personal data”?
Yes — where the person in it is identifiable, a photograph or video is personal data like any other. The DPDP Act’s definition of personal data turns on whether the data relates to an identifiable individual; a clear photo of a person’s face does that as directly as a name or phone number does. This applies whether the image lives in a wedding album, an event recap video, or a photographer’s public portfolio — the format doesn’t change the underlying classification.
The two separate consents: capture and use
Being photographed and having the photo used publicly are different processing activities, and the DPDP Act’s specific-consent principle expects them to be asked about separately.
- Consent to capture — the guest or attendee’s agreement to be photographed or filmed at the event in the first place. For a private event (a wedding, a corporate offsite), this is often reasonably implied by attendance and the client’s own briefing to guests, though a clear notice at entry (“this event is being photographed for the host’s private use”) is the stronger practice.
- Consent to use — a separate question about what happens to the images afterwards: the client’s own use (a wedding album, internal comms), and any further use by the event business or photographer specifically (a public portfolio, social media, a case study). This second layer needs its own clear ask — it isn’t covered by the first.
What this means for different event types
Private and public events sit differently on the capture-consent question, but the use-consent question applies to both.
- Private events (weddings, corporate offsites) — capture consent is reasonably covered by attendance plus the host’s own notice to guests; publishing images beyond the client’s private use (the photographer’s portfolio, social media) needs a separate ask, ideally agreed with the client at booking and communicated to guests.
- Public or semi-public events (conferences, product launches, ticketed events) — capture is more clearly expected as part of attending a publicised event, but portfolio and marketing use by the photographer or event company still needs its own basis, typically set out in the event’s own terms or a clear notice.
- Any event involving minors — needs particular care; a child’s image used in a photographer’s public portfolio or an event business’s marketing should have a parent’s separate, clear consent, not an assumption drawn from a parent bringing the child to the event.
Common mistakes event and photography businesses make
- Treating “the client hired us” as covering the photographer’s own use of images in a public portfolio or social media — the client’s consent doesn’t automatically extend to the photographer’s separate use.
- No notice to guests at private events that photography is happening and what it’s for.
- Publishing event photos with recognisable minors without separate parental consent.
- Sharing full-resolution image sets with third-party vendors (a venue, a caterer, for their own marketing) without the photographed guests’ knowledge.
- Indefinite retention of raw event footage and photo sets, well past any active client or portfolio use.
Collecting and using images compliantly
A short notice at event entry, and a separate portfolio/marketing consent clause agreed with the client at booking, covers most of the gap. For private events, a simple signage or verbal notice that photography is in progress and its general purpose is a reasonable baseline; for the photographer’s or event company’s own further use (portfolio, social proof, case studies), get that as an explicit clause in the client contract, and where individual guests’ recognisable images are used prominently outside the client’s own materials, seek their direct consent rather than relying on the client’s agreement alone.
Drone photography adds a separate problem
A drone shooting an outdoor event captures a materially wider frame than a ground-level camera — often including people who never agreed to be at the event at all, which is a different consent problem from anything covered above. Beyond the DPDP Act’s personal-data question, drone operation itself sits under DGCA (Directorate General of Civil Aviation) rules — registration and pilot-certification requirements that scale with the drone’s weight, zone-based flight restrictions (green/yellow/red zones, with prior permission needed outside green zones), and specific caution around flying over crowds or densely populated gatherings, which describes most outdoor events by definition. On the data side, a wide aerial shot of a wedding lawn or a public function doesn’t stop at the guest list the way a ground photographer’s carefully framed shots can — neighbouring properties, passers-by, and people at an adjacent unrelated gathering can all end up identifiable in the same footage, none of whom gave any consent, capture or otherwise. A photography or event business adding drone coverage should treat it as its own compliance item: confirm the operator’s drone registration and flight authorisation are current before the event, keep the flight path and altitude scoped to the event venue rather than sweeping wider than necessary, and apply extra editorial care before publishing aerial footage — blurring or cropping out clearly identifiable bystanders who aren’t part of the client’s event is often the simpler fix over seeking consent from people there’s no practical way to reach afterward.
FAQ
Does drone photography at an event raise different issues from ground-level photography?
Yes, two separate ones — DGCA’s own drone-operation rules (registration, pilot certification, zone restrictions) apply regardless of the DPDP Act, and the wider aerial frame is more likely to capture identifiable bystanders who never consented to being at the event at all, which calls for more editorial care before publishing the footage.
Does hiring a photographer for an event automatically let them use the photos in their portfolio?
Not automatically — the client’s booking covers the photography service itself; using images publicly (portfolio, social media, marketing) is a separate use that should be agreed explicitly, ideally in the service contract.
Do event guests need to individually consent to being photographed at a private event?
A clear notice that photography is taking place, communicated by the host or visible at the event, is the reasonable baseline for capture; it’s the further use of identifiable images beyond the host’s private purpose that needs a more specific, separate consent.
What extra care applies when children appear in event photos?
Public or marketing use of a recognisable child’s image needs the parent’s separate, explicit consent — attendance at an event with a parent present doesn’t itself cover that further use.
How long should a photography business keep raw event footage?
There’s no fixed retention figure under the DPDP Act — set a written retention period tied to active client and portfolio use, and delete raw footage once neither purpose still applies.